# POL-079 — A charity policy must bar anyone but the charity from using subscriber data

> A charity or donation programme's policy must state that no entity other than the charity itself may use the subscriber data.

- **Rule ID:** POL-079
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** T-Mobile
- **Applies:** Applies when the use case is CHARITY.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-079/

## Why this rule exists

T-Mobile requires this because donor lists are traded more freely than almost any other consumer data, and the donor who gave a number to one cause did not agree to hear from every cause its fundraising agency serves. Charities work through agencies and platforms as a matter of course, so the clause has to say the agency may deliver the messages and nothing else.

## How to fix it

State in the policy that subscriber data is used only by the named charity, and that agencies and platforms handle it solely to deliver the charity's own messages. Done when no other organisation is permitted to use it for anything.

## Example of a compliant value

```text
Numbers given to Riverside Shelter are used only by Riverside Shelter. Our messaging vendor sends the texts on our behalf and uses the numbers for nothing else; no other organisation receives them.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth | `7103` | yes |
